I think a keylogger still has access to at least 2 of my devices
Hi,
I know I may be a "newbie", I second GeorgeSupport6411's post. I may not be a veteran IT guy, but I've made a living online since 1997, I am a loyal MAC user, and NO QUESTION a victim of a MAC hack and / or virus.
When it comes to security, I follow the "best practices" (strong passwords, not using same PW combos, encryption), but I have been through a week of ****. I have a iMac, MacBook Pro, iPad and an iPhone all were hacked as well as Facebook, Gmail, and other accounts.
The ONLY explanation I could come up with is everything is coming downstream FROM MY KEYCHAIN. My brother worked as head of security for Bank of America for nearly a decade and I wanted to ask what all these strange "Kereros" and before I could even say the word he said, "Apple has been having some issues with Kerberos".I
As I understand it, the problem comes in when you can't connect with Kerberos. To me, that sounds easy as clogging your state with other processes or even finding a redirect.
So, I don't think I am out of the woods yet. I think a keylogger still has access to at least 2 of my devices including my iPhone. Rather than bore you with a long protected string of code (I have plenty), can someone look at this and tell me if it looks "normal"?:
This is from a few hours ago:
Mon Feb 13 00:57:00 PST 2017
creating system keychain entries
...Generating key pair...
...creating certificate...
Serial Number : 1F EF 1D 5C
Issuer Name :
Common Name : com.apple.systemdefault
Org : System Identity
Subject Name :
Common Name : com.apple.systemdefault
Org : System Identity
Cert Sig Algorithm : OID : < 06 09 2A 86 48 86 F7 0D 01 01 0B >
alg params : 05 00
Not Before : 08:57:01 Feb 13, 2017
Not After : 08:57:01 Feb 8, 2037
Pub Key Algorithm : OID : < 06 09 2A 86 48 86 F7 0D 01 01 01 >
alg params : 05 00
Pub key Bytes : Length 270 bytes : 30 82 01 0A 02 82 01 01 ...
CSSM Key :
Algorithm : RSA
Key Size : 2048 bits
Key Use : CSSM_KEYUSE_ENCRYPT CSSM_KEYUSE_VERIFY CSSM_KEYUSE_WRAP
Signature : 256 bytes : A6 37 BE 9F 18 31 E5 97 ...
Extension struct : OID : < 06 03 55 1D 0F >
Critical : FALSE
usage : DigitalSignature KeyEncipherment DataEncipherment
Extension struct : OID : < 06 03 55 1D 25 >
Critical : FALSE
purpose 0 : OID : < 06 09 2A 86 48 86 F7 63 64 04 04 >
..cert stored in Keychain.
..identity registered for domain com.apple.systemdefault.
...Generating key pair...
...creating certificate...
Serial Number : 75 6B 04 B4
Issuer Name :
Common Name : com.apple.kerberos.kdc
Org : System Identity
Subject Name :
Common Name : com.apple.kerberos.kdc
Org : System Identity
Cert Sig Algorithm : OID : < 06 09 2A 86 48 86 F7 0D 01 01 0B >
alg params : 05 00
Not Before : 08:57:02 Feb 13, 2017
Not After : 08:57:02 Feb 8, 2037
Pub Key Algorithm : OID : < 06 09 2A 86 48 86 F7 0D 01 01 01 >
alg params : 05 00
Pub key Bytes : Length 270 bytes : 30 82 01 0A 02 82 01 01 ...
CSSM Key :
Algorithm : RSA
Key Size : 2048 bits
Key Use : CSSM_KEYUSE_ENCRYPT CSSM_KEYUSE_VERIFY CSSM_KEYUSE_WRAP CSSM_KEYUSE_DERIVE
Signature : 256 bytes : 4A 72 17 B0 FB 68 B2 9C ...
Extension struct : OID : < 06 03 55 1D 0F >
Critical : FALSE
usage : DigitalSignature KeyEncipherment
Extension struct : OID : < 06 03 55 1D 25 >
Critical : FALSE
purpose 0 : OID : < 06 08 2B 06 01 05 05 07 03 01 >
Extension struct : OID : < 06 03 55 1D 25 >
Critical : FALSE
purpose 0 : OID : < 06 07 2B 06 01 05 02 03 05 >
..cert stored in Keychain.
..identity registered for domain com.apple.kerberos.kdc.
added /System/Library/PrivateFrameworks/Heimdal.framework/Helpers/kdc to acl for com.apple.kerberos.kdc
hod-admin: krb5_kt_start_seq_get: keytab /etc/krb5.keytab access failed: No such file or directory
Done LKDC setup
No matching processes were found
Mon Feb 13 00:57:04 PST 2017
creating system keychain entries
...System identity already exists for domain com.apple.systemdefault. Done.
...System identity already exists for domain com.apple.kerberos.kdc. Done.
/System/Library/PrivateFrameworks/Heimdal.framework/Helpers/kdc already in acl
Done LKDC setup
No matching processes were found